What the vulnerability does
01Description
Authorization Bypass Through User-Controlled Key vulnerability in MarketingFire Editorial Calendar.This issue affects Editorial Calendar: from n/a through 3.7.12.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Authorization Bypass Through User-Controlled Key vulnerability in MarketingFire Editorial Calendar.This issue affects Editorial Calendar: from n/a through 3.7.12.
Explanation of Vulnerability in Simple Terms
MarketingFire Editorial Calendar versions up to 3.7.12 contain an authorization flaw that allows authenticated users to modify data they should not have access to. An attacker with low-level account privileges can alter or corrupt calendar entries and related content. The vulnerability requires valid login credentials but no additional user interaction.
What an attacker can do
Modify or delete calendar entries and data belonging to other users or restricted areas.
Potential impact on your site
Authenticated users can tamper with editorial calendar data, disrupting content planning and publishing workflows.
Conditions required to exploit
Attacker must have a valid low-privilege account on the site.
Key dates
External resources
Related vulnerabilities